ERoko Distributors + Colonial Countertops Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ERoko Distributors and Colonial Countertops were listed by the incransom ransomware group on August 24, 2024, after internal files were taken in an attack whose timing is not established. Anyone connected to either company should verify whether their information was exposed and take protective steps.
ERoko Distributors + Colonial Countertops has been listed by the ransomware group known as incransom, according to a report dated August 24, 2024. Public information indicates that the group claims internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and further details about the incident’s scale or timeline have not been disclosed.
This listing matters because organizations in the building-products distribution sector often hold operational, customer, and employee records. When a ransomware group claims to have taken internal files, those who do business with or work for the company face potential exposure of information that could be misused, even if the exact contents stay unconfirmed.
Breaking down the breach
The available record states only that ERoko Distributors + Colonial Countertops was listed by incransom on or around August 24, 2024, and that the group asserts internal files were exfiltrated in a ransomware attack. No confirmed count of affected individuals, no inventory of specific file types beyond the general description “internal files,” and no public timeline of when systems were first compromised or when encryption may have occurred have been released. Method of initial access, ransom demands, and whether any data has actually been published remain undisclosed. The listing itself is a claim by the group; independent confirmation of the intrusion has not been provided in the public facts.
Who is incransom?
Incransom is a ransomware operation that follows the now-common double-extortion model. Groups of this type typically gain access to a network, move laterally, exfiltrate selected data, and then deploy encryption malware while threatening to release the stolen material if a ransom is not paid. They maintain leak sites on the dark web where they post victim names and, in some cases, sample files to pressure payment. Incransom has appeared in multiple public tracking reports as one of the active ransomware brands that list organizations across manufacturing, distribution, and professional services. Public knowledge of the group’s tactics does not extend to verified statements about this particular victim beyond the listing itself; any assertion that data from ERoko Distributors + Colonial Countertops has been stolen or will be released remains a claim made by the group.
About ERoko Distributors + Colonial Countertops
According to the organization’s own description, E. Roko Distributors has operated for more than 35 years, serving commercial and residential cabinet makers, millworkers, furniture manufacturers, and contractors across British Columbia, Alberta, and the Washington State area. The company stocks thousands of products and delivers them through its distribution facilities, offering volume discounts and one-on-one support. Colonial Countertops appears in the joint name under which the entity was listed, indicating a related or combined operation focused on countertop and cabinetry materials. Businesses of this kind sit in the middle of supply chains that connect manufacturers to builders and remodelers. They routinely process purchase orders, shipping records, pricing agreements, and contact details for both commercial clients and internal staff. A disruption or data exposure at such a distributor can affect order fulfillment, pricing confidentiality, and the personal information of employees and customers who rely on the firm’s services.
The information in question
The only data category named in the public record is “internal files exfiltrated in ransomware attack.” No further breakdown—such as employee records, customer lists, financial documents, or contracts—has been disclosed. Organizations in wholesale distribution typically maintain inventories of product catalogs, customer account files, shipping and billing data, vendor agreements, and human-resources materials. Whether any of those categories were among the files claimed by incransom is unconfirmed. Readers should treat the precise contents as unknown until the company or independent investigators provide verified details.
What's at stake
For individuals whose information may have been among the internal files, the practical risks include possible misuse of contact details, account numbers, or employment data for phishing, identity fraud, or social-engineering attempts. Because the exact data set is unconfirmed, the severity for any single person cannot be assessed from public sources alone. For the organization, a ransomware incident can interrupt order processing, damage supplier and customer trust, and create regulatory or contractual notification obligations. Even when encryption is reversed or systems are restored, the mere claim of data theft can require costly forensic work, legal review, and customer communications. The absence of confirmed numbers of affected people or published samples means the full scope of impact remains an open question.
If your data was in this claimed breach
If you have done business with or worked for ERoko Distributors + Colonial Countertops, treat the listing as a reason for heightened caution rather than confirmed personal exposure. Monitor financial and email accounts for unexpected activity, enable multi-factor authentication where available, and be skeptical of unsolicited messages that reference the company or request sensitive information. Consider placing a fraud alert with credit bureaus if you believe personal identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets elsewhere. Official updates, if any, will come from the company itself or from law-enforcement notifications; until then, the public record remains limited to the group’s claim and the sparse details reported on August 24, 2024.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Association Management Strategies(AAMC.local) Listed by incransom Ransomware GroupCenter for Human Capital Innovation (centerforhci.org) Listed by incransom Ransomware GroupSacred Heart Community Service (shcstheheart.org) Listed by incransom Ransomware GroupLaw Offices of John V. Orrick, P.L. Listed by incransom Ransomware GroupLatest breaches
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.